fix: review 修复——meta 覆盖、重复支付、卸载守卫、测试补全

- EditPost 保存时合并表单中的部分 meta 键,防止插件注入字段覆盖 unlocked_user_ids 等其他键(单篇解锁用户会失去权限的 bug)
- unlockPost:已有阅读权限(会员/作者/已解锁)直接跳文章,不重复支付
- subscribe:已有该套餐有效订阅直接跳我的订阅页
- uninstall:存在已启用的依赖者时拒绝卸载(与 disable 一致)
- .gitignore 排除 storage/media-library/temp 测试残留
- 测试:AdminPagesTest 补 /admin/plugins /admin/payments;新增 Livewire 保存验证 meta 保留、解锁/订阅防重复支付、卸载守卫
This commit is contained in:
ak
2026-08-12 00:53:46 +08:00
parent ec087fe2a8
commit 6a7daa79da
8 changed files with 124 additions and 3 deletions
+2
View File
@@ -22,3 +22,5 @@
Homestead.json Homestead.json
Homestead.yaml Homestead.yaml
Thumbs.db Thumbs.db
/storage/media-library/temp/
+6
View File
@@ -178,6 +178,12 @@ class PluginManager
public function uninstall(string $plugin): void public function uninstall(string $plugin): void
{ {
$dependents = $this->dependents($plugin);
if ($dependents) {
throw new RuntimeException('无法卸载 '.$plugin.':以下已启用插件依赖它:'.implode('、', $dependents).'。请先停用这些插件。');
}
[$vendor, $name] = array_pad(explode('.', $plugin), 2, $plugin); [$vendor, $name] = array_pad(explode('.', $plugin), 2, $plugin);
PluginRecord::query()->where('vendor', $vendor)->where('name', $name)->delete(); PluginRecord::query()->where('vendor', $vendor)->where('name', $name)->delete();
} }
@@ -19,4 +19,14 @@ class EditPost extends EditRecord
DeleteAction::make(), DeleteAction::make(),
]; ];
} }
protected function mutateFormDataBeforeSave(array $data): array
{
// 表单只包含部分 meta 键(插件注入的价格/会员标记等),合并保留其他插件写入的键(如解锁用户)
if (array_key_exists('meta', $data)) {
$data['meta'] = array_merge($this->record->meta ?? [], $data['meta'] ?? []);
}
return $data;
}
} }
@@ -37,6 +37,19 @@ class MembershipController
} }
$user = $request->user(); $user = $request->user();
// 已有该套餐的有效订阅:直接返回我的订阅页,避免重复支付
$active = Subscription::query()
->where('user_id', $user->id)
->where('membership_plan_id', $plan->id)
->where('status', 'active')
->where('ends_at', '>', now())
->exists();
if ($active) {
return redirect()->route('membership.mine');
}
$channel = $request->input('channel', 'alipay'); $channel = $request->input('channel', 'alipay');
$payment = $this->payment->createOrder( $payment = $this->payment->createOrder(
@@ -63,6 +76,13 @@ class MembershipController
public function unlockPost(Request $request, Post $post) public function unlockPost(Request $request, Post $post)
{ {
$user = $request->user();
// 已有阅读权限(会员 / 作者 / 已解锁):直接查看文章,避免重复支付
if ($this->service->canReadPost($user, $post)) {
return redirect()->route('posts.show', $post->slug ?? $post->id);
}
// 单篇付费解锁:创建一笔定向支付 // 单篇付费解锁:创建一笔定向支付
$price = (int) ($post->meta['price'] ?? 0); $price = (int) ($post->meta['price'] ?? 0);
@@ -70,7 +90,6 @@ class MembershipController
abort(404); abort(404);
} }
$user = $request->user();
$channel = $request->input('channel', 'alipay'); $channel = $request->input('channel', 'alipay');
$payment = $this->payment->createOrder( $payment = $this->payment->createOrder(
+6
View File
@@ -50,6 +50,12 @@ class AdminPagesTest extends TestCase
$this->actingAs($this->admin)->get('/admin/media')->assertOk(); $this->actingAs($this->admin)->get('/admin/media')->assertOk();
} }
public function test_plugin_and_payment_pages_load(): void
{
$this->actingAs($this->admin)->get('/admin/plugins')->assertOk();
$this->actingAs($this->admin)->get('/admin/payments')->assertOk();
}
public function test_guest_is_redirected_to_login(): void public function test_guest_is_redirected_to_login(): void
{ {
$this->get('/admin')->assertRedirect('/admin/login'); $this->get('/admin')->assertRedirect('/admin/login');
+38 -1
View File
@@ -112,7 +112,8 @@ class MembershipFlowTest extends TestCase
'content_format' => 'markdown', 'content_format' => 'markdown',
'status' => 'published', 'status' => 'published',
'published_at' => now(), 'published_at' => now(),
'meta' => ['price' => 500], // members_only:非会员被拦截,可单篇支付解锁
'meta' => ['price' => 500, 'members_only' => true],
]); ]);
$this->actingAs($this->user) $this->actingAs($this->user)
@@ -147,4 +148,40 @@ class MembershipFlowTest extends TestCase
$this->assertSame('—', $payment->payable_label); $this->assertSame('—', $payment->payable_label);
$this->assertNull($payment->payable_url); $this->assertNull($payment->payable_url);
} }
public function test_unlock_post_skips_payment_when_already_unlocked(): void
{
$post = Post::create([
'title' => '已解锁',
'slug' => 'already-unlocked',
'content' => '内容',
'content_format' => 'markdown',
'status' => 'published',
'published_at' => now(),
'meta' => ['price' => 500, 'unlocked_user_ids' => [$this->user->id]],
]);
$this->actingAs($this->user)
->post('/posts/'.$post->id.'/unlock')
->assertRedirect('/posts/already-unlocked.shtml');
$this->assertSame(0, Payment::query()->count());
}
public function test_subscribe_skips_payment_when_plan_already_active(): void
{
Subscription::create([
'user_id' => $this->user->id,
'membership_plan_id' => $this->plan->id,
'status' => 'active',
'starts_at' => now(),
'ends_at' => now()->addDays(30),
]);
$this->actingAs($this->user)
->post('/membership/'.$this->plan->id.'/subscribe')
->assertRedirect(route('membership.mine'));
$this->assertSame(0, Payment::query()->count());
}
} }
+15
View File
@@ -83,6 +83,21 @@ class PluginDependencyTest extends TestCase
$this->assertSame(['neatstudio.payment'], $plugins['neatstudio.membership']['dependency_errors']); $this->assertSame(['neatstudio.payment'], $plugins['neatstudio.membership']['dependency_errors']);
} }
public function test_uninstall_plugin_with_enabled_dependent_throws(): void
{
$manager = $this->manager();
try {
$manager->uninstall('neatstudio.payment');
$this->fail('存在已启用的依赖者时应抛出异常');
} catch (RuntimeException $e) {
$this->assertStringContainsString('neatstudio.membership', $e->getMessage());
}
// 卸载失败,记录仍在
$this->assertTrue($manager->isEnabled('neatstudio.payment'));
}
public function test_dependency_problems_for_missing_plugin(): void public function test_dependency_problems_for_missing_plugin(): void
{ {
$manager = $this->manager(); $manager = $this->manager();
+27 -1
View File
@@ -4,10 +4,13 @@ declare(strict_types=1);
namespace Tests\Feature; namespace Tests\Feature;
use App\Filament\Resources\Posts\Pages\EditPost;
use App\Filament\Resources\Posts\PostResource; use App\Filament\Resources\Posts\PostResource;
use App\Models\Post;
use Filament\Schemas\Schema; use Filament\Schemas\Schema;
use Filament\Tables\Table; use Filament\Tables\Table;
use Illuminate\Foundation\Testing\RefreshDatabase; use Illuminate\Foundation\Testing\RefreshDatabase;
use Livewire\Livewire;
use ReflectionClass; use ReflectionClass;
use Tests\TestCase; use Tests\TestCase;
@@ -55,7 +58,7 @@ class PostFormInjectionTest extends TestCase
public function test_meta_price_maps_to_post_meta_json(): void public function test_meta_price_maps_to_post_meta_json(): void
{ {
$post = \App\Models\Post::create([ $post = Post::create([
'title' => '付费文章', 'title' => '付费文章',
'content' => '内容', 'content' => '内容',
'content_format' => 'markdown', 'content_format' => 'markdown',
@@ -67,4 +70,27 @@ class PostFormInjectionTest extends TestCase
$this->assertSame(9900, $post->meta['price']); $this->assertSame(9900, $post->meta['price']);
$this->assertTrue($post->meta['members_only']); $this->assertTrue($post->meta['members_only']);
} }
public function test_edit_post_save_preserves_other_meta_keys(): void
{
$post = Post::create([
'title' => '已解锁文章',
'slug' => 'unlocked-post',
'content' => '内容',
'content_format' => 'markdown',
'status' => 'published',
'published_at' => now(),
'meta' => ['price' => 9900, 'members_only' => true, 'unlocked_user_ids' => [1, 2]],
]);
Livewire::test(EditPost::class, ['record' => $post->getRouteKey()])
->call('save')
->assertHasNoFormErrors();
$post->refresh();
// 表单只含 price/members_only,保存时不得覆盖解锁用户等其他 meta 键
$this->assertSame([1, 2], $post->meta['unlocked_user_ids']);
$this->assertSame(9900, $post->meta['price']);
$this->assertTrue($post->meta['members_only']);
}
} }